VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

MAL-2026-14350None
1mo ago

Malicious code in scrambleeer (PyPI)

Malicious code in scrambleeer (PyPI)

▾ Sunlitscrambleeer · scrambleeervia OSV
MAL-2026-14349None
1mo ago

Malicious code in boto4 (PyPI)

Malicious code in boto4 (PyPI)

▾ Sunlitboto4 · boto4via OSV
MAL-2026-14341None
1mo ago

Malicious code in reqcrypts (PyPI)

Malicious code in reqcrypts (PyPI)

▾ Sunlitreqcrypts · reqcryptsvia OSV
CVE-2026-54457High· 7.7
1mo ago

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied…

▾ Twilighttensorzero · tensorzeroEPSS 0.40%via NVD
CVE-2026-43980Medium· 6.3
1mo ago

Malla is a web analyzer for Meshtastic networks based on MQTT data

Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored in SQLite without sanitization and rendered int…

▾ Sunlitmalla · mallaEPSS 0.33%via NVD
CVE-2026-49360High
1mo ago

Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review

Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.50.0, OSS server deployments that expose the server to an untrusted network without authentication are vulnerable to unauthenticated SQL …

▾ Twilightrecce · recceEPSS 1.1%via NVD
CVE-2026-35163Medium
1mo ago

OctoPrint provides a web interface for controlling consumer 3D printers

OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command and payload.message values in src/…

▾ SunlitOctoPrint · OctoPrintEPSS 0.20%via NVD
CVE-2026-71428Critical· 9.3
1mo ago

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, an…

▾ Midnightunstructured · unstructuredEPSS 0.44%via NVD
CVE-2026-72818High· 7.5PoC
1mo ago

The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded

The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Inpu…

▾ Midnightnltk · nltkEPSS 0.74%via NVD
CVE-2026-71492Medium· 6.5
1mo ago

Banks generates meaningful LLM prompts using a simple template language

Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values in…

▾ Sunlitbanks · banksEPSS 0.47%via NVD
CVE-2026-55558Medium· 5.9
1mo ago

aiosmtplib is an asynchronous SMTP client for use with asyncio

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. A…

▾ Sunlitaiosmtplib · aiosmtplibEPSS 0.40%via NVD
CVE-2026-54770Medium· 6.1
1mo ago

WebOb provides objects for HTTP requests and responses

WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips le…

▾ SunlitRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.42%via NVD
CVE-2026-54623High· 7.1
1mo ago

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint in cms/admin/placeholderadmin.py accepts an attacker-controlled plugin_parent value with…

▾ Twilightdjango-cms · django-cmsEPSS 0.49%via NVD
CVE-2026-54625Medium· 4.8
1mo ago

django CMS is a content management system powered by Django

django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key funct…

▾ Sunlitdjango-cms · django-cmsEPSS 0.18%via NVD
GHSA-5p3m-vhh6-9236Medium· 6.3
1mo ago

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

▾ Sunlitstigmem-node · stigmem-nodevia GHSA
GHSA-jgvr-6x5w-hx5wMedium
1mo ago

Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service

Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service

▾ Sunlitzoo-kcl · zoo-kclvia GHSA
GHSA-mc9m-6fm9-pghcMedium
1mo ago

Zoo Design Studio: Memory-corruption in memory handling of lib-kcl

Zoo Design Studio: Memory-corruption in memory handling of lib-kcl

▾ Sunlitzoo-kcl · zoo-kclvia GHSA
CVE-2026-54259Medium· 4.3
1mo ago

Wagtail: Improper restriction handling on Documents and Images chosen endpoints

Wagtail: Improper restriction handling on Documents and Images chosen endpoints

▾ Sunlitwagtail · wagtailEPSS 0.27%via GHSA
CVE-2026-54260Medium· 4.3
1mo ago

Wagtail: Denial of service via unbounded filter specs in the image preview

Wagtail: Denial of service via unbounded filter specs in the image preview

▾ Sunlitwagtail · wagtailEPSS 0.37%via GHSA
CVE-2026-54261Medium· 6.5
1mo ago

Wagtail: Improper permission handling in image preview

Wagtail: Improper permission handling in image preview

▾ Sunlitwagtail · wagtailEPSS 0.34%via GHSA
CVE-2026-54262Medium· 4.3
1mo ago

Wagtail: Pages translations can be created without page permissions when using simple_translation

Wagtail: Pages translations can be created without page permissions when using simple_translation

▾ Sunlitwagtail · wagtailEPSS 0.27%via GHSA
CVE-2026-54263High· 7.3
1mo ago

Wagtail: Reflected XSS in dynamic image URL generator view

Wagtail: Reflected XSS in dynamic image URL generator view

▾ Twilightwagtail · wagtailEPSS 0.36%via GHSA
CVE-2026-54622Medium· 6.5
1mo ago

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

▾ Sunlitdjango-cms · django-cmsEPSS 0.41%via OSV
CVE-2026-54624Medium· 6.5
1mo ago

django CMS: Structure endpoint bypasses page-view permission

django CMS: Structure endpoint bypasses page-view permission

▾ Sunlitdjango-cms · django-cmsEPSS 0.41%via OSV
CVE-2026-55468Medium· 4.3
1mo ago

Wagtail: Improper restriction handling on Pages admin API

Wagtail: Improper restriction handling on Pages admin API

▾ Sunlitwagtail · wagtailEPSS 0.34%via OSV
CVE-2026-75526Medium· 4.4
1mo ago

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 until 5.0.9, ContentRenderer.render_placeholder in cms/plugin_rendering.py can pass stored, attacker-controlled values…

▾ Sunlitdjango-cms · django-cmsEPSS 0.26%via NVD
CVE-2026-63003Medium· 6.5
1mo ago

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, page duplication lacks an object-level authorization check on the source page. In cms/admin/forms.py, DuplicatePa…

▾ Sunlitdjango-cms · django-cmsEPSS 0.41%via NVD
CVE-2026-61663Medium· 4.3
1mo ago

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

▾ Sunlitdjango-cms · django-cmsEPSS 0.34%via OSV
GHSA-92hv-j533-69wcLow· 3.7
1mo ago

Wagtail: Identification of documents by SHA1 hash

Wagtail: Identification of documents by SHA1 hash

▾ Sunlitwagtail · wagtailvia GHSA
GHSA-c2xx-cjmh-9q8fMedium· 5.3
1mo ago

Wagtail: Improper restriction handling on descendant collections in Documents and Images API

Wagtail: Improper restriction handling on descendant collections in Documents and Images API

▾ Sunlitwagtail · wagtailvia GHSA
CVEs tagged “pip” — page 16 · VulnSea